Description
This affects all versions of package nedb. The library could be tricked into adding or modifying properties of Object.prototype using a __proto__ or constructor.prototype payload.
Remediation
References
https://snyk.io/vuln/SNYK-JS-NEDB-1305279
Related Vulnerabilities
CVE-2022-22885 Vulnerability in maven package cn.hutool:hutool-http
CVE-2016-3081 Vulnerability in maven package org.apache.struts:struts2-core
CVE-2023-26136 Vulnerability in npm package tough-cookie
CVE-2015-8862 Vulnerability in maven package org.webjars.npm:mustache
CVE-2016-10735 Vulnerability in maven package org.webjars.bowergithub.angular-ui:bootstrap